Skip to content
Process

Incident Response

Updated Aug 2026 1 min read
Definition

Incident response is the organized approach to detecting, containing, eradicating, and recovering from security incidents. An incident response plan defines roles, communication procedures, evidence preservation requirements, and escalation paths for different types of security events.

Why It Matters

AI agents introduce new incident categories. A compromised agent session, a prompt injection attack, an agent accessing data outside its intended scope, or an unauthorized MCP server deployment are all incidents that require response procedures.

Agent-specific incident response requires capabilities that traditional IR may not include: the ability to terminate a specific agent session, revoke session-scoped credentials, replay the audit trail of a compromised session, and identify all systems the agent accessed during the incident window.

NIS2 requires organizations in covered sectors to report significant incidents within 24 hours. Agent governance systems that provide immutable audit trails and session-level visibility enable faster incident triage and more accurate impact assessment.